CVE-2025-12464
published 2025-10-31CVE-2025-12464: A stack-based buffer overflow was found in the QEMU e1000 network device. The code for padding short frames was dropped from individual network devices and…
PriorityP427medium6.2CVSS 3.1
AVLACLPRNUINSUCNINAH
EPSS
0.17%
6.5th percentile
A stack-based buffer overflow was found in the QEMU e1000 network device. The code for padding short frames was dropped from individual network devices and moved to the net core code. The issue stems from the device's receive code still being able to process a short frame in loopback mode. This could lead to a buffer overrun in the e1000_receive_iov() function via the loopback code path. A malicious guest user could use this vulnerability to crash the QEMU process on the host, resulting in a denial of service.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | qemu | < qemu 1:10.1.3+ds-1 (forky) | qemu 1:10.1.3+ds-1 (forky) |
| msrc | azl3_qemu_8.2.0-21_on_azure_linux_3.0 | — | — |
| msrc | azl3_qemu_8.2.0-23_on_azure_linux_3.0 | — | — |
| msrc | azl3_qemu_8.2.0-25_on_azure_linux_3.0 | — | — |
| msrc | cbl_mariner_1.0_arm | — | — |
| msrc | cbl_mariner_1.0_x64 | — | — |
| msrc | cm1_kernel_5.4.91-3_on_cbl_mariner_1.0 | — | — |
| qemu | qemu | >= 0 < 1:10.0.7+ds-0+deb13u1 | 1:10.0.7+ds-0+deb13u1 |
| qemu | qemu | >= 0 < 1:10.1.3+ds-1 | 1:10.1.3+ds-1 |
| qemu | qemu | >= 0 < 1:6.2+dfsg-2ubuntu6.28 | 1:6.2+dfsg-2ubuntu6.28 |
| qemu | qemu | >= 0 < 1:8.2.2+ds-0ubuntu1.13 | 1:8.2.2+ds-0ubuntu1.13 |
| qemu | qemu | >= 0 < 1:10.1.0+ds-5ubuntu2.4 | 1:10.1.0+ds-5ubuntu2.4 |
CVSS provenance
nvdv3.16.2MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv6.2MEDIUM
vendor_msrc6.7MEDIUM
vendor_debian6.2LOW
vendor_redhat6.2MEDIUM
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
qemu vulnerabilities
osv·2026-03-04·CVSS 5.5
CVE-2024-8354 [MEDIUM] qemu vulnerabilities
qemu vulnerabilities
It was discovered that the UHCI controller implementation of QEMU could be
brought into an invalid state. An attacker inside the guest could possibly
use this issue to cause QEMU to crash, resulting in a denial of service.
(CVE-2024-8354)
It was discovered that QEMU incorrectly handled memory during certain VNC
operations. An remote attacker could possibly use this issue to cause QEMU
to crash, resulting in a denial of service, or possibly execute arbitrary
code. (CVE-2025-11234)
It was discovered that the e1000 network device implementation of QEMU
could be made to write out of bounds. An attacker inside the guest could
possibly use this issue to cause QEMU to crash, resulting in a denial of
service, or possibly execute arbitrary code. This issue only affected
Ubun
GHSA
GHSA-59fq-gggw-pqjr: A stack-based buffer overflow was found in the QEMU e1000 network device
ghsa_unreviewed·2025-11-01
CVE-2025-12464 [MEDIUM] CWE-121 GHSA-59fq-gggw-pqjr: A stack-based buffer overflow was found in the QEMU e1000 network device
A stack-based buffer overflow was found in the QEMU e1000 network device. The code for padding short frames was dropped from individual network devices and moved to the net core code. The issue stems from the device's receive code still being able to process a short frame in loopback mode. This could lead to a buffer overrun in the e1000_receive_iov() function via the loopback code path. A malicious guest user could use this vulnerability to crash the QEMU process on the host, resulting in a denial of service.
OSV
CVE-2025-12464: A stack-based buffer overflow was found in the QEMU e1000 network device
osv·2025-10-31·CVSS 6.2
CVE-2025-12464 [MEDIUM] CVE-2025-12464: A stack-based buffer overflow was found in the QEMU e1000 network device
A stack-based buffer overflow was found in the QEMU e1000 network device. The code for padding short frames was dropped from individual network devices and moved to the net core code. The issue stems from the device's receive code still being able to process a short frame in loopback mode. This could lead to a buffer overrun in the e1000_receive_iov() function via the loopback code path. A malicious guest user could use this vulnerability to crash the QEMU process on the host, resulting in a denial of service.
Ubuntu
QEMU vulnerabilities
vendor_ubuntu·2026-03-04·CVSS 5.5
CVE-2026-0665 [MEDIUM] QEMU vulnerabilities
Title: QEMU vulnerabilities
Summary: Several security issues were fixed in QEMU.
It was discovered that the UHCI controller implementation of QEMU could be
brought into an invalid state. An attacker inside the guest could possibly
use this issue to cause QEMU to crash, resulting in a denial of service.
(CVE-2024-8354)
It was discovered that QEMU incorrectly handled memory during certain VNC
operations. An remote attacker could possibly use this issue to cause QEMU
to crash, resulting in a denial of service, or possibly execute arbitrary
code. (CVE-2025-11234)
It was discovered that the e1000 network device implementation of QEMU
could be made to write out of bounds. An attacker inside the guest could
possibly use this issue to cause QEMU to crash, resulting in a denial of
service, or p
Microsoft
Qemu-kvm: stack buffer overflow in e1000 device via short frames in loopback mode
vendor_msrc·2025-10-14·CVSS 6.2
CVE-2025-12464 [MEDIUM] CWE-121 Qemu-kvm: stack buffer overflow in e1000 device via short frames in loopback mode
Qemu-kvm: stack buffer overflow in e1000 device via short frames in loopback mode
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
redhat: redhat
Customer Action Required: Yes
Remediation: CBL-Mariner Releas
Red Hat
qemu-kvm: Stack buffer overflow in e1000 device via short frames in loopback mode
vendor_redhat·2025-07-17·CVSS 6.2
CVE-2025-12464 [MEDIUM] CWE-121 qemu-kvm: Stack buffer overflow in e1000 device via short frames in loopback mode
qemu-kvm: Stack buffer overflow in e1000 device via short frames in loopback mode
A stack-based buffer overflow was found in the QEMU e1000 network device. The code for padding short frames was dropped from individual network devices and moved to the net core code. The issue stems from the device's receive code still being able to process a short frame in loopback mode. This could lead to a buffer overrun in the e1000_receive_iov() function via the loopback code path. A malicious guest user could use this vulnerability to crash the QEMU process on the host, resulting in a denial of service.
A stack-based buffer overflow was found in the QEMU e1000 network device. The code for padding short frames was dropped from individual network devices and moved to the net core code. The issue stems
Debian
CVE-2025-12464: qemu - A stack-based buffer overflow was found in the QEMU e1000 network device. The co...
vendor_debian·2025·CVSS 6.2
CVE-2025-12464 [MEDIUM] CVE-2025-12464: qemu - A stack-based buffer overflow was found in the QEMU e1000 network device. The co...
A stack-based buffer overflow was found in the QEMU e1000 network device. The code for padding short frames was dropped from individual network devices and moved to the net core code. The issue stems from the device's receive code still being able to process a short frame in loopback mode. This could lead to a buffer overrun in the e1000_receive_iov() function via the loopback code path. A malicious guest user could use this vulnerability to crash the QEMU process on the host, resulting in a denial of service.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 1:10.1.3+ds-1)
sid: resolved (fixed in 1:10.1.3+ds-1)
trixie: resolved (fixed in 1:10.0.7+ds-0+deb13u1)
Microsoft
usb_sg_cancel in drivers/usb/core/message.c in the Linux kernel before 5.6.8 has a use-after-free because a transfer occurs without a reference aka CID-056ad39ee925.
vendor_msrc·2020-04-14·CVSS 6.7
CVE-2020-12464 [MEDIUM] CWE-416 usb_sg_cancel in drivers/usb/core/message.c in the Linux kernel before 5.6.8 has a use-after-free because a transfer occurs without a reference aka CID-056ad39ee925.
usb_sg_cancel in drivers/usb/core/message.c in the Linux kernel before 5.6.8 has a use-after-free because a transfer occurs without a reference aka CID-056ad39ee925.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mar
No detection rules found.
No public exploits indexed.
2025-10-31
Published